The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not properly validate images, allowing high privilege users such as administrators to upload PHP files disguised as images and containing malicious PHP code
References
| Link | Resource |
|---|---|
| https://wpscan.com/vulnerability/1330f8f7-4a59-4e9d-acae-21656a4101fe | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-05-16 08:15
Updated : 2022-05-24 09:01
NVD link : CVE-2022-1409
Mitre link : CVE-2022-1409
JSON object : View
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
Products Affected
vikwp
- hotel_booking_engine_\&_pms


